Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Mamdani discount grocery store meme shows unrelated photo, false claim about family

    August 1, 2026

    Petrol prices on track to top $2 a litre as Bowen sounds death knell for fuel excise relief | Petrol prices

    August 1, 2026

    What Worries Democrats as the Midterms Heat Up

    August 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Mamdani discount grocery store meme shows unrelated photo, false claim about family
    • Petrol prices on track to top $2 a litre as Bowen sounds death knell for fuel excise relief | Petrol prices
    • What Worries Democrats as the Midterms Heat Up
    • Chinese AI Researchers Are Finding Their Voice on X
    • HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
    • Crypto Today: FTX Creditors Receive $900M Payout, Citadel Buys Situational Assets
    • What Homer’s ‘Odyssey’ Tells Us About the Economics of the Bronze Age
    • Does video show thousands of migrants entering Spanish territory of Cueta? What we know
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 1, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 31, 2026Endpoint Security / Malware

    Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.

    According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that involves privilege escalation, weakening Microsoft Defender protections, and downloading additional payloads.

    While HollowFrame is launched via a DLL side-loading pair comprising the legitimate Python binary (“python.exe”) and a rogue DLL (“python311.dll”), Matryoshka comes in two variants, one which supports HTTP-based communication and command execution, and another that uses GitHub for command-and-control (C2), including beaconing, tasking, reconnaissance, file transfer, and secondary payload delivery.

    “Together, HollowFrame and Matryoshka gave the actor a persistent foothold for remote command execution, Active Directory reconnaissance, file transfer, and deployment of follow-on tooling,” security researchers Nevan Beal and Sam Decker said. “These capabilities could support credential theft, lateral movement, and broader domain compromise through additional tools delivered after initial access.”

    Cybersecurity

    The cybersecurity company said the multi-stage intrusion targeted two endpoints at an unspecified law firm, with the LNK file masquerading as “Case Documents” to trick the recipient into clicking it and activating a command sequence that employs PowerShell to fetch next-stage components from a remote server (“2.26.252[.]84”).

    HollowFrame operates as a modular loader and persistence framework that supports various methods to load auxiliary components, at the same time performing anti-analysis checks to avoid running within sandboxed environments. This is determined based on system uptime, installed memory, file count in the user profile, and cursor movement. Persistence is achieved by setting up a scheduled task.

    The Go loader comes embedded with an encrypted container, which is then unpacked to launch a second side-loading chain to deploy Matryoshka (“version.dll”), a Rust-based backdoor that communicates with its C2 server (“45.158.196[.]184:8888”) over HTTP to spawn a shell and deliver additional tooling.

    A second DLL (“wtsapi32.dll”) recovered in connection with the same activity has been flagged as a variant of Matryoshka that makes use of a private GitHub repository (“adioziaete/memio”) to poll victim-specific commands, submit results, and fetch payloads.

    “The repository functioned as a collection of per-host mailboxes, with each victim assigned a dedicated _ directory,” Blackpoint explained. “These directories contained beacon.json, cmd.json, result.json, and, in some cases, an upload/ tree for file delivery.”

    Cybersecurity

    “This structure allowed the operator to manage tasking and results for individual endpoints through GitHub without maintaining a custom command server, while also leaving a versioned history of repository changes unless the associated commits or repository were removed.”

    Querying the GitHub API with the username shows that the account was created on January 6, 2023, and that the profile information was updated as recently as June 7, 2026. It’s currently not known who is behind the activity.

    “Across the chain, each stage reduced the amount of malicious behavior visible in the stage before it,” Blackpoint noted. “That separation complicated attribution and detection because no single component contained the full infection logic or complete C2 picture.”

    attack Backdoor Deploys firm HollowFrame law Loader Matryoshka SpearPhishing
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Arch Linux disables AUR package adoption to stop malware flood

    Amgen says cloud data breach exposed patient health, proprietary info

    CareCloud Data Breach Impacts Over 350,000

    EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

    Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

    OpenAI says its new GPT 5.6 models are becoming more cost-efficient

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Mamdani discount grocery store meme shows unrelated photo, false claim about family

    August 1, 2026

    Petrol prices on track to top $2 a litre as Bowen sounds death knell for fuel excise relief | Petrol prices

    August 1, 2026

    What Worries Democrats as the Midterms Heat Up

    August 1, 2026

    Chinese AI Researchers Are Finding Their Voice on X

    August 1, 2026
    Latest Posts

    New to Linux? This 10-day checklist will help you settle in nice and easy

    July 22, 2026

    Tories ask HMRC to investigate whether Nigel Farage owes tax on £5m gift | Nigel Farage

    July 22, 2026

    Greece derails EU’s Russia sanctions plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Mamdani discount grocery store meme shows unrelated photo, false claim about family

    August 1, 2026

    Petrol prices on track to top $2 a litre as Bowen sounds death knell for fuel excise relief | Petrol prices

    August 1, 2026

    What Worries Democrats as the Midterms Heat Up

    August 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.